PT-2026-36797 · Apache · Apache Http Server

Y7Syeu

·

Published

2026-05-04

·

Updated

2026-05-05

·

CVE-2026-24072

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP versions prior to 2.4.67
Description An escalation of privilege issue in various modules allows local .htaccess authors to read files using the privileges of the httpd user.
Recommendations Upgrade to version 2.4.67.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-24072

Affected Products

Apache Http Server